A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Qemu | Qemu | 6.0.0 (including) | 7.0.0 (excluding) | 
| Red Hat Enterprise Linux 8 | RedHat | virt-devel:rhel-8060020220408104655.d63f516d | * | 
| Red Hat Enterprise Linux 8 | RedHat | virt:rhel-8060020220408104655.d63f516d | * | 
| Red Hat Enterprise Linux 9 | RedHat | qemu-kvm-17:7.0.0-13.el9 | * | 
| Qemu | Ubuntu | devel | * | 
| Qemu | Ubuntu | impish | * | 
| Qemu | Ubuntu | jammy | * | 
| Qemu | Ubuntu | trusty | * |